THE ROLE, IN PRACTICE
IT Director responsibilities: what the role actually covers, and when to hire or outsource it
If you are reading this, you are probably weighing up whether you need an IT Director, or whether the work can be handled another way. This page sets out the real responsibilities of the role, what good looks like, the signs you have outgrown your current setup, and how a fractional or interim arrangement delivers the same outcomes without a permanent salary.
Book a conversationWhat does an IT Director actually do?
An IT Director owns the technology that runs the business and is accountable for whether it works, whether it is secure, and whether it supports where the company is going. The job sits between two worlds: it translates commercial strategy into a technology plan the board can fund, and it runs the day to day delivery that keeps systems available and staff productive. It is partly leadership, partly architecture, partly risk management, and partly budget control. The title varies, IT Director, Head of IT, CIO, but the accountability is the same: technology is fit for purpose and the business is not carrying risk it has not chosen to carry.
The common mistake is to treat the role as senior IT support. That is a fraction of it. A good IT Director spends more time on decisions that have a multi year cost than on tickets, and the value shows up in fewer outages, lower wasted spend, and a clearer link between what the company invests in technology and what it gets back. This is the same accountability we describe on our fractional CIO and CISO page, simply at a different level of seniority.
The core responsibilities, set out plainly
Strip away the variations between sectors and the role comes down to a handful of areas. First, strategy and planning: setting a technology roadmap that matches business priorities and a budget the board can sign off, which is the heart of IT strategy consulting. Second, infrastructure and operations: making sure networks, servers, cloud services, devices and core applications are available, performing and supportable. Third, security and risk: protecting data and systems, meeting regulatory obligations, and being ready to respond when something goes wrong.
Fourth, people and suppliers: leading the internal team, managing the managed service providers and software vendors, and holding contracts to account on price and performance. Fifth, governance and reporting: giving the board a true picture of technology risk and spend in language they can act on, which is exactly what our board IT strategy work supports. Sixth, change and projects: delivering the systems, migrations and improvements the business needs without breaking what already runs, often the engine room of any digital transformation in the mid market.
- Owning the technology roadmap and the technology budget
- Keeping core systems available, secure and supportable
- Managing the team, the suppliers and the contracts
- Giving the board a clear, honest view of risk and spend
- Delivering change without disrupting the business
Security is no longer a separate job
A decade ago an IT Director could treat security as something that happened in the background. That is no longer credible. The responsibility now includes knowing where your data lives, who can reach it, how you would detect a breach, and how you would recover. The financial stakes are real: the IBM Cost of a Data Breach Report 2025 puts the global average cost of a breach at USD 4.44 million, and UK regulators have shown they will act, with the ICO fining British Airways £20 million in 2020 and Interserve £4.4 million in 2022.
For many organisations the honest position is that the IT Director carries security accountability without dedicated security expertise. That gap is exactly what our CISO as a service and virtual CISO offerings exist to close, alongside practical cyber security consulting. If you are in a regulated sector, expect this to weigh heavier still: see our work on NIS2 compliance and cyber security in financial services. And every IT Director should be able to answer one question without hesitation: what happens in the first hour of a ransomware attack? If the answer is unclear, start with a tested incident response plan and a proper view of ransomware readiness.
What good looks like
A strong IT Director is judged less on the technology and more on the absence of nasty surprises. Systems stay up. Spend is predictable and tied to outcomes the board recognises. Security risk is named, owned and reducing, not quietly accumulating. Projects land when they were promised and do what they said. And the board trusts the technology picture they are being shown, because it has proven accurate before.
The other marker of good is that the IT Director raises issues before they become incidents. They flag the supplier contract that is about to auto renew on poor terms, the ageing system that will not survive the next growth phase, the new use of AI tools across the business that nobody has governed. On that last point, the rise of unsanctioned tools makes AI governance and the problem of shadow AI a live part of the role rather than a future concern.
Signs you need this role filled
You usually do not decide to hire an IT Director in calm conditions. The signals tend to be these: technology decisions keep landing on a finance director or operations lead who has no time for them; outages or security scares are becoming a pattern; you cannot get a straight answer on what you spend on IT or what it returns; a deal, an acquisition or an investor is asking questions you cannot confidently answer. That last case is its own discipline, covered in our technology due diligence work.
There is also the quieter version: the business has grown past the point where part time attention is enough, but not yet to the point where a full time director is justified or affordable. This is the most common position we see, and it is precisely the gap addressed on our interim CIO leadership gap page. If you are unsure which side of the line you are on, the diagnostic linked at the foot of this page is built to tell you.
Hiring versus outsourcing the role
A permanent IT Director is the right answer when technology is central to how you compete, the workload genuinely fills a full time post, and you can attract and keep someone at that level. The cost is significant and goes well beyond salary once you add recruitment, benefits and the risk of a poor hire in a senior seat.
For a large number of mid market and growing organisations, a fractional or interim arrangement delivers the same responsibilities at a fraction of the standing cost. A fractional IT Director, sometimes structured as a virtual CIO, gives you experienced leadership for an agreed number of days, owning the roadmap, the budget, the suppliers and the board reporting, without a permanent headcount. An interim director covers a gap, a transition or a turnaround at full intensity for a defined period. You can compare the economics directly using our CIO and CISO cost calculator, and our pricing page sets out how engagements are structured.
The point of outsourcing is not to do less. It is to get genuine director level judgement, including hard calls on security and board level cyber governance, without paying for seniority you only need part of the week. If you want the fuller explanation of how the fractional model works in practice, our guide to what a vCISO is walks through it.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
That experience, owning technology and security at group level for large UK organisations, is exactly the judgement an IT Director role demands, which is why Starkhorn delivers those responsibilities on a fractional or interim basis rather than as another permanent hire.
Frequently asked questions
What is the difference between an IT Director and a CIO?
The titles overlap heavily. An IT Director typically owns technology operations, infrastructure, security and delivery for the organisation. A CIO is the same accountability framed more around strategy and the boardroom. In smaller and mid market companies they are often the same person under different labels.
Does an IT Director handle cyber security?
Yes, security accountability sits with the IT Director unless there is a dedicated CISO. The risk is that the role carries the responsibility without specialist security depth, which is why many organisations add a fractional CISO alongside their IT leadership rather than expecting one person to cover both at full strength.
Can a fractional IT Director really do the whole job?
For most mid market organisations, yes. The director level work, roadmap, budget, suppliers, security risk and board reporting, does not require a full week. A fractional arrangement gives you that leadership for an agreed number of days while your internal team handles day to day operations.
How do I know if I need an IT Director at all?
Look for the signals: technology decisions falling on people without the time or expertise, recurring outages or security scares, no clear view of IT spend and return, or investor and acquisition questions you cannot answer. If several of those are true, you need the role, the only question is whether permanent, interim or fractional fits best.
What does outsourcing the role cost compared with hiring?
A permanent director carries salary plus recruitment, benefits and hiring risk. A fractional or interim arrangement is paid for the days you actually need, which is usually a fraction of that standing cost. You can model the comparison directly with our cost calculator.
FIND THE GAP
Not sure whether you need an IT Director?
If you are weighing up a permanent hire against an interim or fractional arrangement, start by seeing where your technology leadership actually falls short. The Technology Leadership Gap check is a short, free diagnostic that tells you which responsibilities are uncovered and what to do about them. Or book a conversation and we will talk it through.
Technology Leadership Gap check Book a conversation